🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,898
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 19, 2026
Last Updated

39,898 vulnerabilities found (page 523 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d77e94ad-2bb7-442d-be67-b4f42b3b3107
< 3.12.10
MEDIUM 6.4 The Leaflet Maps Marker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
d77db5be-fa72-45f8-ad87-82cb0d0b4c94
< 1.9
MEDIUM 6.4 The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Block i… wordfence
d77c8096-40b1-4ac7-881f-6aed98da6752
< 2.8.51
MEDIUM 6.4 The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_medi… wordfence
d76052f8-34b3-4930-a5bf-182420b07968
< 0.10.7
MEDIUM 6.4 The DICOM Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dcm' shortcode in … wordfence
d74e8541-9726-4bc2-9fbd-f6016490e0ea
< 1.2.0
MEDIUM 6.4 The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
d74d71a8-774a-4ebb-b254-0e65a8044319
< 3.3.0
MEDIUM 6.4 The GiveWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.2 due… wordfence
d73b4634-1547-41b0-beb5-ae80edd16936
< 1.1.14
MEDIUM 6.4 The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
d7195b51-f88e-4f44-b8fa-484f8c8fdae7
< 1.6
MEDIUM 6.4 The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
d714d740-d7e0-49fd-af08-b4a80c9d0599
< 1.5.6
MEDIUM 6.4 The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider widget in a… wordfence
d6fac092-803f-42ec-8840-bdc929d00d62
< 3.1.4
MEDIUM 6.4 The Notice Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.3… wordfence
d6f3de97-5b87-49e4-9239-f405f72b893a
< 4.0.0
MEDIUM 6.4 The Eventin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.57 d… wordfence
d6f319c1-6bf4-41c7-826f-fb752777ec14
< 3.2.1
MEDIUM 6.4 The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.0… wordfence
d6ea95b5-9e1c-41b1-9bc5-5fd5cecef65d
< 1.5.6
MEDIUM 6.4 The Primary Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Prici… wordfence
d6e8b7b6-d7f8-4b2a-a5f9-ef2d2560d12b MEDIUM 6.4 The Adverts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4 due … wordfence
d6e1335c-17f8-4162-95c1-7b6a9cc94c94
< 1.9.5
MEDIUM 6.4 The tarteaucitron.io plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embed' shortcod… wordfence
d6d8cf85-6925-4bd9-83e4-88e4dba430ed MEDIUM 6.4 The Amilia Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9… wordfence
d6cc17a6-994c-4ac4-8175-263add849b1b
< 4.5.0
MEDIUM 6.4 The Logo Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Brand Name" field in all vers… wordfence
d6c277f4-28e0-4159-a524-6576d72d2059
< 2.5
MEDIUM 6.4 The AD Sliding FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliding_faq' shortcode in … wordfence
d6bf752e-56be-42fc-b2d7-0a9658287c3b MEDIUM 6.4 The Sidebar-Content from Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
d6bc11cd-157f-403f-90db-071208902d1c MEDIUM 6.4 The CoverManager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.0… wordfence
d6b37e1b-ebfb-49dd-a7b8-73ace468b893 MEDIUM 6.4 The Posts for Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
d6a73a7f-53ac-4930-a1cd-c39818f64678
< 2.8.9
MEDIUM 6.4 The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortc… wordfence
d6a1eb50-c482-4ae2-8d34-798997a12c33
< 2.7.9.1
MEDIUM 6.4 The JetElements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
d69cfed9-7369-40f3-b9a7-0cf2430e8eed
< 4.4.9
MEDIUM 6.4 The ChatBot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘openai_settings_option_callback… wordfence
d6934c0e-7526-4de7-9478-3c953b3dc64f
< 8.5.6
MEDIUM 6.4 The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Stored Cro… wordfence
← Prev 520 521 522 523 524 525 526 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top